Security & Vulnerability Reporting
A private contact point for reporting security issues that may affect TycoonX accounts, data, purchases, entitlements, infrastructure, or users.
Report a security issue privately
Please send security reports to cevikdev@gmail.com with the subject TycoonX Security.
Do not post exploit details, credentials, private user data, access tokens, or unreleased security information in public chat, app reviews, social media, public issue trackers, or community channels.
What to include
- The affected TycoonX platform and app version, where known.
- A concise description of the issue and its potential security impact.
- Minimal reproduction steps that CK-Labs can use to verify the issue safely.
- Relevant timestamps, request IDs, screenshots, or logs with secrets and unrelated personal data removed.
- Whether you believe the issue is being actively exploited or is causing an ongoing security incident.
Safe testing expectations
A good-faith report does not require proving impact by harming another player or extracting real user data. Stop testing once you have enough information to demonstrate the issue safely.
- Do not access, alter, delete, transfer, or publish another person's account or data.
- Do not use denial-of-service, destructive automation, spam, social engineering, credential stuffing, malware, or physical attacks.
- Do not create fraudulent purchases, abusive chargebacks, payment disputes, entitlement duplication, or economy transfers as a security test.
- Do not retain secrets, tokens, credentials, payment data, private messages, or other personal data beyond what is strictly necessary to report the issue.
- Do not demand payment or threaten disclosure, disruption, or data release.
This page does not authorize access to third-party systems, conduct prohibited by law, or activity outside systems CK-Labs is entitled to authorize.
How CK-Labs handles reports
CK-Labs may validate, reproduce, contain, remediate, document, and monitor a reported issue, and may temporarily restrict a vulnerable TycoonX feature where reasonably necessary to protect users, purchases, game integrity, or infrastructure.
Security-related account, purchase, or entitlement corrections are reconciled against authoritative TycoonX, Apple, Google, Xsolla, and other relevant provider records where applicable. Mandatory consumer and data-protection rights remain unaffected.
Where law requires security reporting or user notification, CK-Labs may provide necessary information to the competent authority, CSIRT, ENISA, platform, payment provider, affected user, or other legally relevant recipient, while limiting personal data and sensitive exploit details to what is necessary and lawful.
No automatic bounty
CK-Labs does not promise a cash reward, Diamond reward, VIP entitlement, credit, or other compensation for a report unless a specific reward or bug-bounty arrangement was expressly offered in advance. A voluntary thank-you or goodwill reward in one case does not create a right to the same reward in another case.
Other TycoonX support
For ordinary account recovery, billing, refunds, gameplay issues, moderation, or privacy requests that are not security vulnerabilities, use the normal TycoonX support and legal routes.
Last updated: August 28, 2026